http://www.forbes.com/sites/investor/2014/01/14/cybersecurity-becomes-central-to-u-s-interests/print/



*1/14/2014 @ 12:08PM **|**303 views *

*Cybersecurity Becomes Central To U.S. Interests*

Josh Wolfe <http://www.forbes.com/sites/joshwolfe/>,

*[image:
http://b-i.forbesimg.com/investor/files/2014/01/0926_cyber-criminal_270x190.jpg]**The
excerpt below comes from Forbes/Wolfe Emerging Technology Report’s  recent
full-length interview in with Dr. Peter Singer, senior fellow and director
of the Center for 21 Century Security and Intelligence at the Brookings
Institution.*

*What inspired you to write **Cybersecurity and Cyberwar: What Everyone
Needs to Know?*

*Peter Singer:* I was inspired by our ever-increasing dependence on
computers, and the concern that this dependence is now being exploited in
many different ways. I wanted to educate my readers and myself about the
dangers of Internet security because I believe there is a profound lack of
knowledge on these issues. There is no field that has emerged as rapidly as
cybersecurity.

Seventy percent of executives, whether in the technology industry or the
paint industry, are dealing with cybersecurity questions—and yet no major
MBA program is teaching them how to handle the risks. The only books that
were out on this subject were either highly technical or highly histrionic.

The key leaders involved in adjudicating these issues don’t have even the
most basic understanding the technology. Eight of the nine U.S. Supreme
Court Justices don’t use email! We tried to write a book that wrestles with
the key questions in an easy-to-understand manner, and to have a little fun
along the way.

*How do people protect themselves in an arena that didn’t even exist 30
years ago?*

*Singer*: One of the key lessons of our book is that while there is an
amazing amount of change going on in this space, there are some things that
remain the same. Many of the methods to protect yourself and your
organization haven’t changed.

People need to learn basic Internet hygiene. Just as we teach children not
to pick up foreign objects off the ground and eat them, we should teach
people not to plug in foreign objects into their computers. Arguably the
biggest penetration in U.S. military history took place when a soldier
found a USB key on the ground and plugged it into his computer. At the end
of the day, if you want to stay safe, don’t just look to the technology,
look to the people operating it.

*What has the U.S. government done to respond to these dramatic changes?*

*Singer*: In the Pentagon’s 2014 budget, which just a couple years ago
didn’t once mention the word “cyber,” the word appears 147 times. An
investor told me that Internet security spending growth cannot be described
as a boom, but rather a balloon. By one measure the industry will reach
$165 billion in size in a couple of years.

*Does this explosive growth in cybersecurity spending make you feel more
comfortable with the future of America’s cyber defenses?*

*Singer*: Yes and no. I remember speaking with the Chairman of the Joint
Chiefs, and the question that I posed was: for every extra dollar that you
spend on this, are you getting a 1% gain in capability, a 10% gain or a
10,000% gain? Maybe for every dollar you’re only getting a one-cent gain in
capability. We don’t have a good answer to that. Throwing money at the
problem is not how you gain cybersecurity. It’s more about organization,
mentality and training. That holds not only for the military but also for
organizations and businesses.

*Does the U.S. government take an offensive or defensive approach to
Internet security?*

*Singer*: On the military side, there is this assumption that cyber offense
helps with cyber defense. As a result, senior leadership is investing
approximately four times as much on cyber offense research by the Pentagon
as cyber defense research. The generals argue that they’d rather be the
ones shooting the bullets rather than figuring out how to defend against
them, and that’s a natural inclination.

But the problem is that if you live in a glass house, maybe your best
investment is not to continually try to build sharper and sharper stones.
Maybe we should be investing in turning glass into bulletproof glass.

*What do you think about the tone of our national conversation around this
topic?*

*Singer*: The problem with our national discussion is that it’s easier and
frankly more lucrative for Internet security specialists to turn the
proverbial volume up to 11 and use phrases like “cyber 9/11,” which has now
been used in the media more than a quarter of a million times. People often
push that notion of cataclysmic fear with personal profit as the motive.

In reality, the big worry for our nation isn’t a “cyber 9/11,” but instead
it’s death by a thousand cuts—the gradual but colossal loss of intellectual
property through cyber espionage. We need to understand the differences of
the threats that we face, and recognize how we use the term “cyber-attack”
in so many different ways.

The way we talk about cyberattacks would be like taking the phenomena of
kids with fire crackers carrying out a prank, a robber with a pistol
stopping you in an alleyway, a terrorist planting a roadside bomb, and a
military firing a cruise missile, and saying all of these things are the
same because they involve the chemistry of gunpowder.

We need to change our national conversation so that we can understand and
disentangle the different threats that we face.

*Can you give some examples of the various types of cyber threats we face?*

*Singer*: There is a vast range of threats. Some are generic threats that
aren’t aimed at individuals, but at everyone, such as the infamous Nigerian
Prince scam. Then there are advanced persistent threats, when individuals
or businesses are targeted by dedicated organizations with a specific goal,
be it a negotiating strategy for your firm or a secret design for something
that you’re building.

Additionally, there exist organizations, typically large governments that
can carry out sophisticated attacks that cause physical, rather than
informational damage. An example of physical damage through cyber warfare
can be seen when the United States used software to cause Iranian nuclear
centrifuges

to spin out of control. This method can be used to attack anything from
factories to traffic lights. On the other end of the spectrum, some nations
out there consider Miley Cyrus
<http://www.forbes.com/profile/miley-cyrus/>tweets to be an
informational attack.

*How has the Edward Snowden case changed the way people look at the
Internet?*

*Singer*: In a post-Snowden world, we have to become very worried about the
future of the Internet itself. This tool that we know, love and use every
day has been so good to us in terms of information sharing, recreation,
communication and the boom in the global economy, is also changing—and the
worry is that it’s becoming not only more insecure but also more
militarized and more balkanized.

More borders are being thrown up in the name of security when ulterior
motives may be at play. The Internet that I grew up with that helped change
the world in so son will know and recognize.

*Can you describe how one can maintain good “Internet hygiene?”*

*Singer*: There are a series of simple things that people can do to protect
themselves. No one should think this is an unsolvable problem. Our body
doesn’t just stop threats at skinlevel.  Rather, it has developed systems
to eject and fight off viruses and keep on functioning.

Just as people exercise to maintain physical health, organizations at all
levels should be exercising their network defenses by testing firewalls and
testing systems so that they’re prepared rather than waiting for the bad
thing to happen. Passwords only offer one line of defense, and are quite
vulnerable to compromised servers or brute force hacking attacks. For more
valuable information and accounts we should be using multifactor
authentication. None of these are 100% solutions, but these simple fixes
are making the attackers’ jobs harder.

*Are there any surprising facts that you’ve learned in your investigation?*

*Singer*: A poll of IT security specialists working within major
corporations showed that 40% of them at some point had to spend time
debugging an executive’s computer from malware they had unintentionally
downloaded from visiting porn sites. These poor IT specialists are spending
their time cleaning up after executives’ porn habits rather than protecting
their business from real dangers. Also, shockingly, the most popular
password is “password.” The second-most popular choice is “123456.”

*What do you think about the growth of Tor and the Dark Web?*

*Singer*: If you’re telling an honest history of the Internet, you have to
discuss the important role that the pornography world played in spurring on
so many new technologies that have become the norm. Instant messaging, chat
rooms, online purchasing, streaming video, trading files and Webcams all
were originally born in the smut industry. Similar innovations are taking
place to preserve anonymity, such as Tor and Bitcoin.

Unfortunately, there is a woeful lack of awareness and understanding on
this topic among senior policy leaders. Interestingly, Tor was developed
using Pentagon research money and has been supported by the State
Department, which has strong interest in sharing it with dissident groups
in authoritarian countries to allow them to communicate without being
hunted down.

At the same time, according to the revelations from the Edward Snowden
documents, if you use this tool that was paid for by the Pentagon and
supported by the State Department, you are now flagged to be included in
the wide sweep of NSA collection data. This is technology that’s used both
by human rights activists as well as by child pornographers. Understanding
this duality is important, rather than trying to make some kind of blanket
assessment of any single technology.

*What do you want readers to take away from your book?*

*Singer*: The extent of the present and future threats that loom, both
known and unknown, makes cyberspace seem such an incredibly intimidating
and scary place. The key takeaway from our book is that it need not be.

The same kind of lessons and basic rules that held true 10 years ago, hold
today, and will hold tomorrow. The answer is still the same: build proper
understanding and enact thoughtful responses.

*Excerpted from December issue of Forbes/Wolfe Emerging Tech Report
<http://www.newsletters.forbes.com/store?Action=DisplayPage&Locale=en_US&id=ProductDetailsPage&SiteID=es_764&productID=53889200&pgm=67634400>.*




------------------------------



*This article is available online at:
http://www.forbes.com/sites/investor/2014/01/14/cybersecurity-becomes-central-to-u-s-interests/
<http://www.forbes.com/sites/investor/2014/01/14/cybersecurity-becomes-central-to-u-s-interests/>*




__._,_.___





__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.

<<image001.jpg>>

Reply via email to